• DocumentCode
    3259214
  • Title

    Evaluation of Online Resources in Assisting Phishing Detection

  • Author

    Bian, Kaigui ; Park, Jung-Min ; Hsiao, Michael S. ; Bélanger, France ; Hiller, Janine

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Virginia Tech, Blacksburg, VA, USA
  • fYear
    2009
  • fDate
    20-24 July 2009
  • Firstpage
    30
  • Lastpage
    36
  • Abstract
    Phishing is an attempt to fraudulently acquire userspsila sensitive information, such as passwords or financial information, by masquerading as a trustworthy entity in online transactions. Recently, a number of researchers have proposed using external online resources like the Google Page Rank system to assist phishing detection. The advantage of such an approach is that the detection capability will gradually evolve and improve as the online resources become more sophisticated and manipulation-resistant. In this paper, we evaluate the effectiveness of three popular online resources in detecting phishing sites-viz, Google PageRank system, Yahoo! Inlink data, and Yahoo! directory service. Our results indicate that these online resources can be used to increase the accuracy of phishing site detection when used in conjunction with existing phishing countermeasures. The proposed approach involves examining the following three attributes of a target site (site being examined): (1) the credibility of the target sitepsilas hosting domain, (2) the credibility of in-neighbor sites that link to the hosting domain, and (3) the correlation between the target sitepsilas web category and its hosting domainpsilas web category. The aforementioned online resources by themselves are insufficient to address the phishing attack problem. We provide discussions on how each of those resources may be integrated with existing phishing detection techniques to provide a more effective solution.
  • Keywords
    Web sites; computer crime; search engines; Google PageRank system; Web-based information theft; Yahoo! Inlink data; Yahoo! directory service; external online resources; hosting domain Web category; online resources evaluation; online transactions; phishing countermeasures; phishing site detection; target site Web category; user sensitive information; Application software; Finance; Information systems; Insurance; Internet; Uniform resource locators; World Wide Web;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Applications and the Internet, 2009. SAINT '09. Ninth Annual International Symposium on
  • Conference_Location
    Bellevue, WA
  • Print_ISBN
    978-1-4244-4776-3
  • Electronic_ISBN
    978-0-7695-3700-9
  • Type

    conf

  • DOI
    10.1109/SAINT.2009.14
  • Filename
    5230664